Security1 distinct publisher3 min readPublished
The distributor found the intrusion on August 25, 2026, the same day ShinyHunters says its four-day exfiltration ended. It has not named the vendor applications involved, so customers are left scoping their own integrations.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Two accounts sit side by side, and they should be read separately. McKesson's own filing and customer notice confirm an incident discovered on August 25, 2026 [4], unauthorized access to third-party applications, and exfiltration of data [6]. The company has not said which applications, how access was obtained, or what was taken [8]. Everything about mechanism comes from the extortionist: ShinyHunters told BleepingComputer it ran vishing against multiple employees, took over their Okta single sign-on accounts, and used those to reach Salesforce and Snowflake [9][12]. It claims the Salesforce environment including support cases, and a larger patient-related set out of Snowflake [13].
The volume claim is checkable against itself. About 1TB moved between August 21 and August 25 [14], and roughly 284 million records is a raw line count rather than a count of people, per ShinyHunters' correction to earlier reporting [15]. Divide: 1e12 bytes over 2.84e8 records averages about 3.5 KB each [1]. Since the terabyte also carries the Salesforce case data, the true per-row average for the Snowflake set is lower still [1]. That is the size of tabular rows, not of patient files with attachments. ShinyHunters says it has not analyzed the data and does not know the unique-individual count [16], so nobody currently has a defensible number for how many patients are involved.
The timeline lines up too neatly to ignore. The claimed transfer window closes on the same date McKesson gives as its discovery date [2], which puts detection at the end of four days of egress averaging roughly 250 GB per day [3]. Whether the discovery interrupted the transfer or merely observed its finish is not in the public record [8].
The initial access route matches a known campaign pattern. A second BleepingComputer source identified mckesson[.]claims as part of the campaign [10], and ReliaQuest said it is tracking widespread ShinyHunters registration of company[.]claims domains carrying a target's name or abbreviation to impersonate help desks and IT [11]. That gives cheap detection material for anyone else in the healthcare supply chain: newly registered .claims domains matching your name, help desk reset volume, and bulk export rates in Salesforce and Snowflake tenants federated to the same identity provider.
Nothing in either account describes malware or a vulnerability [8][12]. Endpoint hardening does not touch this chain. The reachable set is whatever the SSO entitlement trusts, so the inventory that matters is which third-party applications hold patient data, which of them sit behind the same IdP, and what query and export ceilings exist inside each one. McKesson meanwhile says materiality is undetermined and that it is not proactively disconnecting systems, while warning customers of intermittent service degradation tied to the attack [5][7].
Ranked by verification strength, evidence, and original report placement.
ShinyHunters declined to provide many technical details including the domain used, but BleepingComputer learned from another source that the threat actors used the mckesson[.]claims domain as part of the attack.
ReliaQuest said in a now-deleted post on X that it is tracking a widespread ShinyHunters campaign using domains following the company[.]claims pattern, incorporating the target organization's name or abbreviation under the .claims TLD to impersonate help desks and IT teams.
McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.
McKesson is a major U.S. healthcare company and pharmaceutical distributor providing medicines, medical supplies, technology and services to healthcare providers and pharmacies.
CyberInsider first reported the breach, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission.
McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
ShinyHunters dumps 12.9 million Carhartt records after a refused $3.3 million ransom1 distinct publisher
invest
Nvidia's FY2028 guide reprices analysts' revenue models by about 18%1 distinct publisher
product
RingCentral lost 1.6 million records to a phone call, not a missing patch1 distinct publisher
security
One VPS, Two SaaS Platforms: A Portal Scraper That Has Not Moved Since March 20251 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
A filing outline plus the attackers' own account
Two things hold this up, and only one is accountable. McKesson's 8-K and customer notice confirm the shape — third-party applications, data taken, August 25 discovery — and nothing more: no application named, no access path, no data types. Every specific in the story comes from ShinyHunters, and BleepingComputer says plainly it could not verify any of it. The lookalike domain is the exception with a second leg, sourced independently and matching ReliaQuest's company[.]claims research, though that research has since been pulled from X.
Real disclosure, unmeasured reach
This is past the rumour stage: there is an 8-K, a customer notice, a live degradation warning, and a named place on McKesson's own site for updates. There is also a pattern — Health-ISAC's warning and five other health technology names hit by the same group. What is missing is anything that measures reach: no count of affected individuals, no notification wave, no named applications, and a record total the attackers themselves say they have not resolved into people.
The headline number shrank when someone asked
'284 million patients' survived until a reporter put the question to the group, which then described it as 284 million rows and conceded it has not analysed the data. That is the whole gap in miniature: an unpaid extortion crew — precise to the dollar at $55,236,150 — has every reason to talk in volumes, and volumes are what got amplified. Pushing the other way, McKesson's 'not material' arrived three days after discovery with the investigation admittedly early, which is understatement of a different kind. On net the public number still runs ahead of what anyone has counted.
Everyone quoted has a reason to shade the number
The load here is unusually lopsided. An extortion group whose 72-hour deadline lapsed unanswered is the source for volume, scope and access path — inflation is its remaining leverage. McKesson, filing three days in, pre-commits to no material impact before it can know. And the threat intelligence vendor that corroborated the domain pattern deleted its own post, which tells you even the disinterested party is managing what it says in public.
Firm on the disclosure, provisional on everything inside it
We can be confident about what was filed, when detection happened, and what the company declined to say — those come from documents. Confidence drops sharply on the intrusion itself, because a single outlet talking to the perpetrators is the only window into it and no second newsroom appears in our coverage to test it. The dates that matter align in a way that will not change: discovery on the last day of the claimed egress window.